Ghost Accounts Abuse GitHub API in Mass Recon Campaign
2026-07-12T19:24:03Z•00497fc7494df544f48a47b4aff89c4e4bc7424ac71fa8b3ac5eae56f268e2fd
AI-hallucinationsAPI-abuseBlackCat/AlphvChina-linked-activity','India-linked-activity','Pakistan','BaloEntra-IDGigaWiperGitHubGo-moduleHalluSquattingMicrosoft-365OktaPowerShellbotnetdead-dropghost-accountsmalicious-repositoriesmalwaremass-reconnaissancenation-statephishingransomwareransomware-negotiationsupply-chainvishingwiper
What happened
Collection of SecurityWeek stories covering multiple high-impact threats and developments: ghost accounts abusing the GitHub API for mass reconnaissance of organizations (repos and members); a network of ~200 malicious GitHub repositories using a Go module to stage PowerShell-based Windows malware via public dead-drops; GigaWiper—a backdoor with wiper, ransomware and multi-pass wiping capabilities—used for destructive system-level sabotage; Okta warnings of vishing campaigns that steer Microsoft 365 users to Entra ID phishing pages; ‘HalluSquatting’ attacks that weaponize AI hallucinations to達
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 00497fc7494df544f48a47b4aff89c4e4bc7424ac71fa8b3ac5eae56f268e2fd
- Enrichment time
- 2026-07-12T19:24:03Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.